Threat Database Trojans Trojan.Lamer.CC

Trojan.Lamer.CC

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 5,247
Threat Level: 80 % (High)
Infected Computers: 515
First Seen: May 30, 2021
Last Seen: July 30, 2026
OS(es) Affected: Windows

The detection of Trojan.Lamer.CC on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operations, symptoms, and most importantly, the steps you can take to remove it from your computer.

What Is Trojan.Lamer.CC?

Trojan.Lamer.CC is identified as a Trojan-type threat, which is a broad category of malware designed to deceive users by appearing as legitimate software. Trojans can cause significant harm by allowing unauthorized access to your system, stealing sensitive information, or installing additional malware. The name itself does not directly imply a specific malware family but indicates its nature as a Trojan horse-type malware.

How Trojan.Lamer.CC Operates

Trojan.Lamer.CC, like other Trojans, operates by disguising itself as a legitimate program or file to gain entry into your system. Once inside, it can perform a variety of malicious activities, including but not limited to, data theft, installation of additional malware, or providing backdoor access to your system. Trojans often exploit vulnerabilities in software or use social engineering tactics to trick users into installing them. Understanding how Trojans operate is crucial for taking preventive measures against such threats.

Symptoms of Infection

The symptoms of a Trojan infection can vary widely depending on the specific goals of the malware. Common signs include unexpected changes to your system settings, appearance of unfamiliar programs or icons, slow system performance, frequent crashes, or unusual network activity. Sometimes, Trojans may not exhibit any noticeable symptoms, making them difficult to detect without proper security software.

  • Unexplained changes in system settings or performance
  • Appearance of unfamiliar programs or icons
  • Frequent system crashes or freezes
  • Unusual or increased network activity

How to Remove Trojan.Lamer.CC

Removing Trojan.Lamer.CC requires a systematic approach to ensure that all components of the malware are eliminated from your system. Follow these steps carefully:

  1. Boot your computer in Safe Mode with Networking to restrict the malware's ability to run and limit its network access.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the Trojan.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed around the time the Trojan was detected.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that the Trojan has been completely removed.

Conclusion

The removal of Trojan.Lamer.CC is crucial to protect your system and data from further harm. By understanding the nature of this threat and following the removal steps outlined above, you can effectively eliminate the malware from your computer. It's also important to adopt preventive measures, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when opening email attachments or downloading files from the internet. Remember, vigilance and prompt action are key to maintaining the security and integrity of your digital environment.

Analysis Report

General information

Family Name: Trojan.Lamer.CC
Signature status: No Signature

Known Samples

MD5: fdf516953f0c4aaccfcf6efe5966e8a7
SHA1: f4fa918ab30b10f3524475995179832423e7f13d
SHA256: C86E1645E57D9290297D0590ADE305623F411BCF77D59B2F2A3AF5FE8B80B7B1
File Size: 56.32 KB, 56320 bytes
MD5: 117f0e8c2ff50376f158c3b8c9262832
SHA1: fc8261b2ef401e508dc507719c67c413490cc607
SHA256: 4375B598A816B7FB4759CA64240DC61CDFE4B4CAA08AAA9BA92BB6A3789D5C68
File Size: 198.14 KB, 198144 bytes
MD5: 7d220902c2349f03c5684f98f4100740
SHA1: 96942312d6f450d4e2a16875bd4ef218ddc9c7a2
SHA256: 923221F55AD221686C3DFA652F37AC56051F52FBAD3017F07AFC7BA5276B34BB
File Size: 296.96 KB, 296960 bytes
MD5: 4fafcd2596c0466a539102b33956ecea
SHA1: c07fd0129cf76fade44def42bdaec29cc1f7ab1d
SHA256: 4E4753FF45BDA02380DED6921A6073E985E4E59A66A59CE802D483CD3313AFAC
File Size: 3.02 MB, 3015261 bytes
MD5: 47030193ac8b58b3ef80b1ed71695677
SHA1: 69021b3ce627ca38a6df4852299ac437e9fb95ec
SHA256: C8EB268E115C898BFD18DAE7C39AD2C373CFC0ECA68563BA4B1CB4F65D8D8222
File Size: 37.89 KB, 37888 bytes
Show More
MD5: 6a3fed0375fac55524fb8d725ddb4d90
SHA1: e0b952d1244058b36113b0d99193c6e677e627ac
SHA256: 0BB9FE40490DE75116C1F7D20CF9B861A66692A2F289D294E964C37458805C8B
File Size: 25.09 KB, 25088 bytes
MD5: 85fdfd3ab1ea2dad13e609c807f55124
SHA1: 8dfc66aceec9992effd43b01d5b508b522ae7c3d
SHA256: 78E19DF5B0C4A94644599F8832CCAB6C8D579CEFF6894024C264B87464495B31
File Size: 1.87 MB, 1866752 bytes
MD5: df50379b533f8b7508e57bdb3b1c7bdd
SHA1: 3ff28e199e0f47433c1d89cf999be0f7df6cbaca
SHA256: 8A1F06CFC4FC98456BC2E2247DD14B156F41D4CF147673C12CA3AA7FD8FBE045
File Size: 30.21 KB, 30208 bytes
MD5: 67ccb814c7973bc2c16c2f35ead006b8
SHA1: 7f82a5f4f1fdca82ac88e170955d36f135422bb1
SHA256: 189EB06D49A2FB771014A7E249CE3F12D4602CB1CE0626F67841A929CD587CD3
File Size: 127.49 KB, 127488 bytes
MD5: 842ed84766964cfeb51319597c9a1f54
SHA1: 1e60b88c4a93e63c02826c3b13017affa0f317ce
SHA256: E05D4516E1D60E07F7B0E3164182A1438363047BB1856234B94E3850BABE22E0
File Size: 163.33 KB, 163328 bytes
MD5: 8b66b463f49d000d244d3cb7f08ee297
SHA1: 57efd1aeb1c086fc1615a475ef60e29c260bc517
SHA256: 2105000BC5D751A2CF1CD4BB0826B4BC174065440510E8CEACF78AEFA492F406
File Size: 25.60 KB, 25600 bytes
MD5: 17506a2d1c47b6dd2724cf2c86f09fac
SHA1: 226c229a2500c1a217f452eedd6431eba137996c
SHA256: DE1AFF555849D6BF20F112589DB0423A90C8115F5785BBF8D82EEDA9D94DEEA4
File Size: 169.98 KB, 169984 bytes
MD5: 475b385cd874824ad02c01a41ac266fa
SHA1: dc0e8bb7c93841eed54f68d808d86567f65c591a
SHA256: 0A0805903538E804FF5D202AC3286BE268B99753B6236DC2E0F5895273BFB399
File Size: 25.09 KB, 25088 bytes
MD5: 04aa763ca20cd1fe9b703e0cee6a383a
SHA1: fd1d8a947ae2624383657db16d393706359056ff
SHA256: A6E9468641C092CE3F13EEF5AB1B0E8D00256AA9BA00B047F8958990BC585B86
File Size: 26.62 KB, 26624 bytes
MD5: f56406d89217116f01cb75e919fb0073
SHA1: c1660a9cae49d463e42e269133bb1387b691e9bd
SHA256: 74DC71CD92C0DDBC16AA80F2383BDFC844B3178CF8962BCE8F598048284263FD
File Size: 26.11 KB, 26112 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Show More

Windows PE Version Information

Name Value
Company Name
  • ATENOR B.M. S.L.
  • By L00gh@nJC... 2014
  • grandesjuegosclasicos
  • KC PHONE & FLASH
  • Oussama Gravure CD-DVD
  • TT
File Description
  • Activate Maps,Voices, Speedcams & Fuel prices. Patch Navcore & HOME. Check current meta code. Update QuickGPSfix
  • BY PORTAL PORTABLES BRASIL
  • Deletes Unused Comports from Device MNGR.
  • GiNi4EveR
  • Juego portable de NDS para Windows
File Version
  • 1.00
  • 01,09,2016,1800
  • 1,0,0,0
Internal Name
  • Comport Cleaner
  • FastActivate
  • http://www.OussamaDvD.tk
  • TJprojMain
Legal Copyright
  • 2012 - 2013 (c)
  • TT
Original Filename TJprojMain.exe
Product Name
  • Comport Cleaner
  • FastActivate
  • http://www.OussamaDvD.tk
  • Project1
Product Version
  • 1.00
  • 01,09,2016,1800
  • 1,0,0,0

File Traits

  • 2+ executable sections
  • HighEntropy
  • MPRESS
  • MPRESS Win32
  • Native MPRESS x86
  • No Version Info
  • packed
  • x86

Block Information

Total Blocks: 3
Potentially Malicious Blocks: 0
Whitelisted Blocks: 2
Unknown Blocks: 1

Visual Map

? 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • AutoHotkey.A
  • Bitcoinminer.R
  • CoinMiner.BB
  • Emotet.AAJ
  • Emotet.AAL
Show More
  • Kryptik.FHE
  • MPRESS Packer
  • Strictor.A
  • Tofsee.BP
  • Upatre.WIA

Files Modified

File Attributes
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\2173.tmp\register.bat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\26b4.tmp\launch.bat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\2e79.tmp\ngservice(32).bat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\68b1.tmp\apagar windows.bat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\b897.tmp\desoculta.bat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\bb94.tmp\enviadat.bat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\d9fd.tmp\controle.bat Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\f61d.tmp\d.cmd Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\f61d.tmp\devcon.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\f61d.tmp\hklm-ccset-control-comnamearbiter000000.reg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\f61d.tmp\m.txt Generic Write,Read Attributes
c:\f61d.tmp\m2.txt Generic Write,Read Attributes
c:\f61d.tmp\rapi.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\f61d.tmp\regutl.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\f61d.tmp\remove hidden.bat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\f61d.tmp\remove.cmd Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\f61d.tmp\rmhiddev_nt.bat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\f61d.tmp\sleep.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\f61d.tmp\tee.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\f61d.tmp\timeout.exe Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ~�$ xy kP~�ރ �����^ ۴� }��Vs}2kP~2��1���O� ���d B F e���1���h�n�} e�� e�� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 장틦᛺ǜ RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �vP xykP~ �ރ������^۴�+}��Vs}pkP~p��1|��,���dB 6F e�b��1X��h �n�}e��e�� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 몽왉ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � xy* �/��Y�d�kP~� ��ރ�p��^�o�ee3Vs}kP~��1.��7 ���ﺃee��� ��1 ��fe��g� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �j�8��81��B �6 �v y� �Z xy �� �a ۀT�B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9�/��1`1� RegNtPreCreateKey
HKCU\local settings\software\microsoft\windows\shell\muicache::c:\windows\system32\regedit.exe.friendlyappname Registry Editor RegNtPreCreateKey
HKCU\local settings\software\microsoft\windows\shell\muicache::c:\windows\system32\regedit.exe.applicationcompany Microsoft Corporation RegNtPreCreateKey
HKLM\software\wow6432node\vuescan\license\activationkey:: 114658838 RegNtPreCreateKey
HKLM\software\wow6432node\vuescan\license\customernumber:: 987063252 RegNtPreCreateKey
HKLM\software\wow6432node\vuescan\license\emailaddress:: michurin@yahoo.com RegNtPreCreateKey
HKCU\software\vuescan\license\activationkey:: 114658838 RegNtPreCreateKey
HKCU\software\vuescan\license\customernumber:: 987063252 RegNtPreCreateKey
HKCU\software\vuescan\license\emailaddress:: michurin@yahoo.com RegNtPreCreateKey

Windows API Usage

Category API
Process Shell Execute
  • CreateProcess
  • ShellExecuteEx
  • WriteConsole
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
Show More
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiAnyLinkedFonts
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateRectRgn
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiDoPalette
  • win32u.dll!NtGdiDrawStream
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiExtTextOutW
  • win32u.dll!NtGdiFlush
  • win32u.dll!NtGdiFontIsLinked
  • win32u.dll!NtGdiGetCharABCWidthsW
  • win32u.dll!NtGdiGetDCDword
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiGetDIBitsInternal
  • win32u.dll!NtGdiGetEntry
  • win32u.dll!NtGdiGetFontData
  • win32u.dll!NtGdiGetGlyphIndicesW
  • win32u.dll!NtGdiGetOutlineTextMetricsInternalW
  • win32u.dll!NtGdiGetRandomRgn
  • win32u.dll!NtGdiGetRealizationInfo
  • win32u.dll!NtGdiGetTextFaceW
  • win32u.dll!NtGdiGetTextMetricsW
  • win32u.dll!NtGdiGetWidthTable
  • win32u.dll!NtGdiHfontCreate
  • win32u.dll!NtGdiIntersectClipRect
  • win32u.dll!NtGdiPatBlt
  • win32u.dll!NtGdiPolyPatBlt
  • win32u.dll!NtGdiPolyTextOutW
  • win32u.dll!NtGdiQueryFontAssocInfo

69 additional items are not displayed above.

Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Terminate
  • TerminateProcess
Other Suspicious
  • SetWindowsHookEx
Keyboard Access
  • GetKeyState
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

open \68B1.tmp\Apagar Windows.bat
WriteConsole:
WriteConsole:
C:\WINDOWS\system32\shutdown.exe shutdown -s -t 0
WriteConsole: Access is denied
Show More
open \26B4.tmp\Launch.bat
WriteConsole: The system canno
WriteConsole: 'DeSmuME.exe' is
"\B897.tmp\Desoculta.bat"
"\D9FD.tmp\controle.bat"
C:\WINDOWS\system32\mode.com MODE con cols=80 lines=25
C:\WINDOWS\system32\net.exe NET session
open \BB94.tmp\ENVIADAT.bat
WriteConsole: GOTO was unexpec
"\F61D.tmp\Remove.cmd" c:\users\user\downloads\
c:\F61D.tmp\devcon.exe DEVCON FIND USB*
c:\F61D.tmp\devcon.exe devcon findall =Modem
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /S /D /c" type m.txt "
C:\WINDOWS\system32\findstr.exe findstr /i /v "bluetooth PdaNet SoftV92 matching Agere FUNC_02 AuthenTec"
c:\F61D.tmp\devcon.exe devcon findall =Ports
C:\WINDOWS\system32\findstr.exe findstr /i /v "PdaNet SoftV92 matching bluetooth printer AuthenTec"
C:\WINDOWS\system32\reg.exe reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}"
C:\WINDOWS\system32\findstr.exe findstr /c:"{4D36E96D-E325-11CE-BFC1-08002BE10318}\\"
C:\WINDOWS\system32\reg.exe reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E978-E325-11CE-BFC1-08002BE10318}"
C:\WINDOWS\system32\findstr.exe findstr /c:"{4D36E978-E325-11CE-BFC1-08002BE10318}\\"
c:\F61D.tmp\regutl.exe regutl "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports"
C:\WINDOWS\system32\findstr.exe findstr /i "COM"
c:\F61D.tmp\regutl.exe regutl "HKLM\SYSTEM\CurrentControlSet\Control\COM Name Arbiter" :ComDB
C:\WINDOWS\system32\find.exe find "ComDB=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00"
C:\WINDOWS\system32\xcopy.exe XCOPY C:\WINDOWS\SYSTEM32\DRIVERS\ser2pl.sys "C:\WINDOWS\Temp\PL-2303_loggedDrv\" /c /h
c:\F61D.tmp\HKLM-CCset-Control-COMNameArbiter000000.reg "HKLM-CCset-Control-COMNameArbiter000000.reg"
c:\F61D.tmp\devcon.exe DEVCON RESCAN
c:\F61D.tmp\Timeout.exe TIMEOUT 3
"\2173.tmp\register.bat"
C:\WINDOWS\system32\reg.exe reg delete HKEY_LOCAL_MACHINE\SOFTWARE\VueScan\license /f
C:\WINDOWS\system32\reg.exe reg delete HKEY_CURRENT_USER\SOFTWARE\VueScan\license /f
C:\WINDOWS\system32\reg.exe reg delete HKEY_CURRENT_USER\SOFTWARE\Wow6432Node\VueScan\license /f
C:\WINDOWS\system32\reg.exe reg add HKEY_LOCAL_MACHINE\SOFTWARE\VueScan\license\ActivationKey /t REG_SZ /d 114658838
C:\WINDOWS\system32\reg.exe reg add HKEY_LOCAL_MACHINE\SOFTWARE\VueScan\license\CustomerNumber /t REG_SZ /d 987063252
C:\WINDOWS\system32\reg.exe reg add HKEY_LOCAL_MACHINE\SOFTWARE\VueScan\license\EmailAddress /t REG_SZ /d michurin@yahoo.com
C:\WINDOWS\system32\reg.exe reg add HKEY_CURRENT_USER\SOFTWARE\VueScan\license\ActivationKey /t REG_SZ /d 114658838
C:\WINDOWS\system32\reg.exe reg add HKEY_CURRENT_USER\SOFTWARE\VueScan\license\CustomerNumber /t REG_SZ /d 987063252
C:\WINDOWS\system32\reg.exe reg add HKEY_CURRENT_USER\SOFTWARE\VueScan\license\EmailAddress /t REG_SZ /d michurin@yahoo.com
"\2E79.tmp\ngService(32).bat"